|  |  |  | 
| Event Class | Any | Select to search for events based on the event class or facility to which they belong. Add Facilities or Event Classes dialog: 
| 2  | Click Add and select one of the following options: |  
| 4  | Click OK to save selection and close dialog. |  NOTE: Use Add With Events to limit the list to events that already have an event in the database. | 
| Object Class | Change Auditor for Active Directory | Select to search for changes to specific object classes (classSchema objects). Add Object Classes dialog: 
| 3  | Click OK to save selection and close dialog. |  NOTE: Use Add With Events to limit the list to object classes that already have an event in the database. | 
| Severity | Any | Select to search for events based on the severity assigned. Add Severities dialog: 
| 3  | Click OK to save selection and close dialog. |  NOTE: Use Add With Events to limit the list to severities that already have an event associated with it in the database. | 
| Result | Any | Select to search for events based on the results of the operation mentioned in the event. Add Results dialog: 
| 3  | Click OK to save selection and close dialog. |  NOTE: Use Add With Events to select from a list of results that already have an event associated with it in the database. | 
| Active Directory | Change Auditor for Active Directory | Select to search for changes to objects in selected Active Directory containers. Add Active Directory Container dialog: You can also select Import Objects to import a .csv file of a list of directory objects. Using this list, you can search for an exact object name or use a wildcard.  
| 2  | Click Add to add to selection list. |  
| 3  | Click in Scope cell to change the scope of the search. |  
| 4  | Click in Actions cell to change setting. All Actions  is selected by default, meaning all activity associated with the object will generate an event. |  
| 5  | Click in Transports cell to change setting. All Transports  is selected by default, meaning all AD query operations regardless of the transport protocol used will be included in the search. |  
| 6  | Click OK to save selections and close dialog. |  NOTE: Use Add Wildcard to specify a wildcard expression to search for Active Directory objects. NOTE: Use Add With Events to select from a list of Active Directory containers that already have an event associated with it in the database. NOTE: Use Add Enterprise to add the enterprise to the selection list. When this option is selected, all other containers in the selection list are ignored (appear in red). Also, the scope setting cannot be changed. | 
| AD Query | Change Auditor for Active Directory Queries  ChangeAuditor for LDAP (v 5.x) | Select to search for a specific Active Directory query that was performed against a specified Active Directory object. Add Active Directory Container dialog: 
| 2  | Click Add to add to selection list. |  
| 3  | Click in Scope cell to change the scope of the search. |  
| 4  | Click in Filter cell to search for an LDAP filter string used in an Active Directory query. |  
| 5  | Click in Attributes cell to search for attributes that are being queried. |  
| 6  | Click in Results cell to search for queries that return a specific number of results. |  
| 7  | Click in Elapsed cell to search for queries that take a specific amount of time to complete. |  
| 8  | Click in Transports cell to change setting. All Transports  is selected by default, meaning all Active Directory queries regardless of the transport protocol used will be included in the search. |  
| 9  | Click OK to save selections and close dialog. |  NOTE: Use Add With Events to select from a list of objects that already have an event in the database. NOTE: Use Add Enterprise to search the entire enterprise. When this option is selected, all other objects in the selection list are ignored (appear in red). Also, the scope, filter, attributes, results and elapsed settings cannot be changed. | 
| ADAM (AD LDS) | Change Auditor for Active Directory | Select to search for changes to objects in selected ADAM (AD LDS) containers. Add ADAM (AD LDS) Container dialog: 
| 3  | Click OK to browse the selected instance. If prompted, enter the credentials to be used to access the selected ADAM (AD LDS) instance. |  
| 5  | Click Add to add to selection list. |  
| 6  | Click in Scope cell to change the scope of the search. |  
| 7  | Click in Actions cell to change setting. All Actions  is selected by default, meaning that all activity associated with the object will generate an event. |  
| 8  | Click in Transports cell to change setting. All Transports  is selected by default, meaning that all AD query operations regardless of the transport protocol used will be included in the search. |  
| 9  | Click OK to save selection and close dialog. |  NOTE: Use Add With Events to select from a list of ADAM (AD LDS) containers that already have an event associated with it in the database. NOTE: Use Add Enterprise to search the entire enterprise. When this option is selected, all other containers in the selection list are ignored (appear in red). Also, the scope setting cannot be changed. | 
| Microsoft Entra  | Change Auditor for Active Directory | Select to search for changes in Microsoft Entra ID. Add Microsoft Entra dialog: | 
|   |   | 
| 8  | Click Add to add the expression to the selection list. |  NOTE: Use Add Wildcard to specify a wildcard expression to search for Microsoft Entra ID changes. NOTE: Use Add With Events to select from a list of Microsoft Entra ID changes that already have an event associated with it in the database. NOTE: Use Add all events to add all Microsoft Entra events.  | 
| Exchange | Change Auditor for Exchange | Select to search for changes to objects in selected Exchange containers. Add Exchange Container dialog: You can also select Import Objects to import a .csv file of a list of directory objects. Using this list, you can search for an exact object name or use a wildcard.  
| 2  | Click Add to add to selection list. |  
| 3  | Click in Scope cell to change the scope of the search. |  
| 4  | Click in Actions cell to change setting. All Actions  is selected by default, meaning all activities associated with the object will generate an event. |  
| 5  | Click in Transports cell to change setting. All Transports  is selected by default, meaning that all AD query operations regardless of the transport protocol used will be included in the search. |  
| 6  | Click OK to save selection and close dialog. |  NOTE: Use Add Wildcard to specify a wildcard expression to search for Exchange containers. NOTE: Use Add With Events to select from a list of Exchange containers that already have an event associated with it in the database. NOTE: Use Add Enterprise to search the entire enterprise. When this option is selected, all other containers in the selection list are ignored (appear in red). Also, the scope setting cannot be changed. | 
| Microsoft 365 Exchange Online NOTE: Use Add With Events to select from a list of Exchange Online mailboxes that already have an event associated with them in the database. NOTE: Expand Add All and select one of the following to search for ‘all’ Microsoft 365 Exchange Online events: All Microsoft 365 Exchange Online Events , All Microsoft 365 Exchange Online Mailbox Events , or All Microsoft 365 Exchange Online Administration Events . When one of these options is selected, all other entries in the selection list are ignored (appear in red). | Change Auditor for Exchange | Select to search for changes to a specific Exchange Online mailbox. Microsoft 365 Exchange Online dialog: 
| 2  | If Mailbox Event is selected: |  
| • | Select Mailbox Name and/or Folder Name , select the comparison operator to be used: Contains  or Does not contain . Enter the name (or partial name) of a mailbox/folder to be used to search for a match. (Case sensitivity is based on your SQL setting). Click Add to add criteria to selection list. |  If both the Mailbox Name and Folder Name  are specified, both expressions must be met. 
| • | Select On-Premises User Name, select the comparison operator to be used: Like  or Not like and enter the name (or partial name) to be used to search for a match. (Case sensitivity is based on your SQL setting.) Click Add  to add the criteria to the selection list. |  
| • | Select On-Premises Target Name or Target Display Name, select the comparison operator to be used: Like  or Not like and enter the name (or partial name) to be used to search for a match. Case sensitivity is based on your SQL setting. Click Add  to add the expression to the selection list.  |  
| • | Select Target Sync Type, select In cloud to include mailbox accounts created in the cloud or Synced from AD  to include mailbox accounts that have been synchronized from your on-premises Active Directory directories. Click Add  to add the expression to the selection list. |  | 
|   |   | If Administration Cmdlet Event is selected: 
| • | Select Cmdlet and/orCmdlet Object  check box. |  
| • | Click Add to add criteria to selection list. |  
| • | Click OK to save the selection and close the dialog. |  | 
| File System | One of the following: Change Auditor for Windows File Systems Change Auditor for NetApp Change Auditor for EMC | Select to search for specific file system events. Add File System Path dialog: 
| 2  | Click Add to add to selection list. |  
| 3  | Click in Scope cell to change the scope of the search. |  
| 4  | Click in Actions cell to change setting. All Actions  is selected by default, meaning that all activity associated with the file system will be included in the search. |  
| 5  | Click in Types cell to change setting. All Types  is selected by default, meaning all file system path types will be searched. |  
| 6  | Click OK to save selections and close dialog. |  NOTE: Use Add With Events to select from a list of file system paths that already have an event associated with it in the database. NOTE: Use Add All File System Paths to search all file system paths. When this option is selected, all other file system paths in the selection list are ignored (appear in red). Also, the Scope and Types settings cannot be changed. | 
| Group Policy | Change Auditor for Active Directory | Select to search for changes to objects in selected Group Policy containers. Add Group Policy Container dialog: You can also select Import Objects to import a .csv file of a list of directory objects. Using this list, you can search for an exact object name or use a wildcard.  
| 3  | Click OK to save selections and close dialog. |  NOTE: Use Add Wildcard to specify a wildcard expression to search for Group Policy containers. NOTE: Use Add With Events to select from a list of Group Policy containers that already have an event associated with it in the database. NOTE: Use Add All Group Policies to search all group policies in the enterprise. When this option is selected, all other containers in the selection list are ignored (appear in red). | 
| Local Account | Any | Select to search for changes to users or groups that reside in local SAM databases of a member server. Add Local Account dialog: 
| 3  | Click OK to save selections and close dialog. |  NOTE: Use Add All Local Accounts to search all local accounts in the enterprise. When this option is selected, all other accounts in the selection list are ignored (appear in red). | 
| Logon Activity | Change Auditor for Logon Activity User for server agents Change Auditor for Logon Activity Workstation for workstation agents | Select to search for a specific type of logon event. Add Logons dialog: 
| 3  | Click OK to save selections and close dialog. |  NOTE: Use Add With Events to select from a list of logon types that already have an event in the database. | 
| Registry | Any | Select to search for changes to system registry keys that already have an event associated with it in the Change Auditor database. Add Registry Key dialog: 
| 3  | Click in Scope cell to change the scope of the search. |  
| 4  | Click in Actions cell to change setting. All Actions  is selected by default, meaning all registry key actions will be included in the search. |  
| 5  | Click OK to save selections and close dialog. |  NOTE: Use Add All Registry Keys to search all registry keys in the enterprise. When this option is selected, all other registry keys in the selection list are ignored (appear in red). In addition, the Scope cannot be changed. | 
| Service | Any | Select to search for changes to services which already have an event associated with it in the Change Auditor database. Add Service dialog: 
| 3  | Click OK to save selections and close dialog. |  | 
| SharePoint | Change Auditor for SharePoint | Select to search for changes to specific SharePoint components. Add SharePoint Path dialog: 
| 4  | Click OK to save selections and close dialog. |  NOTE: Use Add With Events to limit this list to SharePoint paths that already have an event associated with it in the database. NOTE: Use Add All SharePoint Paths to search all SharePoint paths in the enterprise. When this option is selected, all other paths in the selection list are ignored (appear in red). | 
| SQL | Change Auditor for SQL Server | Select to search for changes to specific SQL instances. Add SQL Instance dialog: 
| 4  | Click Add to add criteria to selection list. |  
| 5  | Click OK to save selections and close dialog. |  NOTE: Use Add With Events to select from a list of SQL instances that already have an event associated with it in the database. NOTE: Use Add All SQL Instances to search all SQL instances in the enterprise. When this option is selected, all other instances in the selection list are ignored (appear in red). | 
| SQL Data Level | Change Auditor for SQL Server | On the Add SQL Data Level Object, select one of the following and enter the search term:  
| 2  | Click OK to save your selection and close the dialog. |  |